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LISTING OF CLAIMS 



The listing of claims replaces all previous listings of claims: 

Claim 1 (previously presented): A method for securing an accessible computer system, 
the method comprising: 

monitoring a computer system for connection transactions between multiple access 
requestors and multiple access providers using a switching component connected to the multiple 
access providers; and 

denying access by an attacking access requestor to the access providers when a number of 
connection transactions initiated by the attacking access requestor through the switching 
component exceeds a configurable threshold number during a first configurable period of time. 

Claim 2 (previously presented): The method as in claim 1, wherein the monitoring 
includes detecting connection transactions initiated by the access requestors through the 
switching component. 

Claim 3 (previously presented): The method as in claim 2, wherein the monitoring 
further includes counting the number of connection transactions initiated by the access requestors 
through the switching component during the first configurable period of time. 

Claim 4 (currently amended): The method as in claim 3, wherein the monitoring further 
includes comparing the number of connection transactions initiated by the access requestors 
through the swithing switching component during the first configurable period of time to the 
configurable threshold number. 

Claim 5 (previously presented): The method as in claim 1, wherein the monitoring 
includes detecting connection transactions between multiple Internet protocol addresses and the 
access providers with the switching component. 
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Claim 6 (currently amended): The method as in claim 5, wherein the monitoring further 
includes counting the number of connection transactions initiated through the swithing switching 
component by the Internet protocol addresses during the first configurable period of time. 

Claim 7 (previously presented): The method as in claim 6, wherein the monitoring 
further includes comparing the number of connection transactions initiated by the Internet 
protocol addresses through the switching component during the first configurable period of time 
to the configurable threshold number. 

Claim 8 (original): The method as in claim 6, wherein the monitoring includes 
monitoring a computer system for connection transactions made using TCP. 

Claim 9 (previously presented): The method as in claim 5, wherein the detecting 
includes identifying the Internet protocol addresses through the use of a header attached to a 
message representing the connection transaction being detected. 

Claim 10 (previously presented): The method as in claim 1, wherein the denying of 
access includes denying access to the access providers through the switching component by the 
attacking access requestor for a second configurable period of time. 

Claim 1 1 (previously presented): The method as in claim 10, wherein the denying of 
access further includes resetting the second configurable period of time after detecting a new 
connection transaction initiated by the attacking access requestor through the switching 
component during the second configurable period of time. 

Claim 12 (previously presented): The method as in claim 1, wherein the denying of 
access includes denying access to the access providers through the switching component by the 
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attacking access requestor for a second configurable period of time after detecting a most recent 
connection transaction initiated by the attacking access requestor through the switching 
component. 

Claim 13 (previously presented): The method as in claim 1, wherein the access 
requestors are clients and the access providers are hosts such that the monitoring includes 
detecting connection transactions through the switching component between multiple clients and 
multiple hosts. 

Claim 14 (previously presented): The method as in claim 3, wherein the counting further 
comprises counting a cumulative number of connection transactions for the multiple access 
providers connected to the switching component initiated by each of the access requestors during 
the first configurable period of time. 

Claim 15 (previously presented): A system for securing an accessible computer system, 
comprising: 

means for a switching component connected to multiple access providers to: 
monitor a computer system for connection transactions between multiple access 

requestors and the multiple access providers; and 

deny access by an attacking access requestor to the access providers when a number of 

connection transactions initiated by the attacking access requestor exceeds a configurable 

threshold number during a first configurable period of time. 

Claim 16 (previously presented): The system of claim 15, wherein the means for the 
switching component includes: 

means for detecting connection transactions initiated by the access requestors through the 
switching component; 
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means for counting the number of connection transactions initiated by the access 
requestors through the switching component during the first configurable period of time; and 

means for comparing the number of connection transactions initiated by the access 
requestors through the switching component during the first configurable period of time to the 
configurable threshold number. 

Claim 17 (previously presented): The system of claim 15, wherein the means for the 
switching component includes: 

means for detecting connection transactions between multiple Internet protocol addresses 
and the access providers using the switching component; 

means for counting the number of connection transactions initiated by the Internet 
protocol addresses through the switching component during the first configurable period of time; 
and 

means for comparing the number of connection transactions initiated by the Internet 
protocol addresses through the switching component during the first configurable period of time 
to the configurable threshold number. 

Claim 18 (original): The system of claim 17, wherein the means for monitoring includes 
means for monitoring a computer system for connection transactions made using TCP. 

Claim 19 (previously presented): The system of claim 17, wherein the means for 
detecting includes: 

means for identifying the Internet protocol addresses through the use of a header attached 
to a message representing the connection transaction being detected. 

Claim 20 (previously presented): The system of claim 15, wherein the means for the 
switching component includes: 
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means for denying access to the access providers through the switching component by the 
attacking access requestor for a second configurable period of time. 

Claim 21 (previously presented): The system of claim 20, wherein the means for denying 
access further includes: 

means for resetting the second configurable period of time after detecting a new 
connection transaction initiated by the attacking access requestor through the switching 
component during the second configurable period of time. 

Claim 22 (previously presented): The system of claim 15, wherein the means for the 
switching component includes: 

means for denying access to the access providers through the switching component by the 
attacking access requestor for a second configurable period of time after detecting a most recent 
connection transaction initiated by the access requestor. 

Claim 23 (currently amended): The system of claim 15, wherein the access requestors 
are clients and the access providers are hosts such that the means for the switching component 
includes: 

means for detecting connection transactions through the switching component between 
multip e l multiple clients and multiple hosts. 

Claim 24 (previously presented): The system of claim 16, wherein the means for 
counting further comprises means for counting a cumulative number of connection transactions 
for the multiple access providers connected to the switching component initiated by each of the 
access requestors during the first configurable period of time. 

Claim 25 (previously presented): A system for securing an accessible computer system, 
comprising: 
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a switching component connected to multiple access providers to: 

monitor a computer system for connection transactions between multiple access 

requestors and multiple access providers; and 

deny access by the access requestor to the access providers when a number of 

connection transactions initiated by an attacking access requestor exceed a configurable 

threshold number during a first configurable period of time. 

Claim 26 (previously presented): The system of claim 25, wherein the switching 
component comprises: 

a detection component that is structured and arranged to detect connection transactions 
initiated by the access requestors through the switching component; 

a counting component that is structured and arranged to count the number of connection 
transactions initiated by the access requestors through the switching component during the first 
configurable period of time; and 

a comparing component that is structured and arranged to compare the number of 
connection transactions initiated by the access requestors through the switching component 
during the first configurable period of time to the configurable threshold number. 

Claim 27 (previously presented): The system of claim 25, wherein the switching 
component comprises: 

a detection component that is structured and arranged to detect connection transactions 
through the switching component between multiple Internet protocol addresses and the access 
providers; 

a counting component that is structured and arranged to count the number of connection 
transactions initiated through the switching component by the Internet protocol addresses during 
the first configurable period of time; and 
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a comparing component that is structured and arranged to compare the number of 
connection transactions initiated through the switching component by the Internet protocol 
addresses during the first configurable period of time to the configurable threshold number. 

Claim 28 (original): The system of claim 27, wherein the connection transactions include 
connections made using TCP. 

Claim 29 (previously presented): The system of claim 27, wherein the detection 
component comprises: 

an identifying component that is structured and arranged to identify the Internet protocol 
addresses through the use of a header attached to a message representing the connection 
transaction being detected. 

Claim 30 (previously presented): The system of claim 25, wherein the switching 
component comprises: 

an access preventer that is structured and arranged to deny access to the access providers 
through the switching component by the attacking access requestor for a second configurable 
period of time. 

Claim 31 (previously presented): The system of claim 30, wherein the switching 
component further comprises: 

a timing component that is structured and arranged to measure the second configurable 
period of time during which the access preventer denies access to the access providers by the 
attacking access requestor. 

Claim 32 (previously presented): The system of claim 31, wherein the switching 
component further comprises: 
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a reset component that is structured and arranged to reset the timing component after 
detecting a new connection transaction initiated by the attacking access requestor through the 
switching component during the second configurable period of time. 

Claim 33 (previously presented): The system of claim 25, wherein the switching 
component comprises: 

an access preventer that is structured and arranged to deny access to the access providers 
through the switching component by the attacking access requestor for a second configurable 
period of time after detecting a most recent connection transaction initiated by the access 
requestor. 

Claim 34 (previously presented): The system of claim 25, wherein the access requestors 
are clients and the access providers are hosts such that the switching component comprises: 

a detection component that is structured and arranged to detect connection transactions 
through the switching component between multiple clients and multiple hosts. 

Claim 35 (previously presented): The system of claim 26, wherein the counting 
component further comprises counting a cumulative number of connection transactions for the 
multiple access providers connected to the switching component initiated by each of the access 
requestors during the first configurable period of time. 

Claim 36 (previously presented): The system of claim 25, wherein a host computer 
system receives communications from the switching component. 

Claim 37 (previously presented): The system of claim 25, wherein the switching 
component is included in a host computer system. 



